Cyber attacks are one of the most important issues these days. The threats are many and attackers have many tools at their disposal to target unsuspecting users. A significant threat is the so-called banking malware, which in most cases are banking trojans that steal user credentials.
Here we will look at some of the most dangerous and sophisticated banking malware that have targeted organizations and users.

First, however, we will explain the basic concepts of trojan and banking malware.
What is banking malware and how does it work?
A banking malware/Trojan is a malicious program that attempts to gain access to confidential information stored or processed through online banking systems.
In general, trojan is a very common term when talking about banking malware. Banking trojans appear as legitimate applications, but in reality they try to steal information and avoid detection. For this reason they have also been called trojan malware. This name is given by the classic Trojan Horse trick in the Trojan War.
See also: Malicious Telegram installer installs Purple Fox malware on infected machines
Unfortunately for the average person, banking trojans are highly sophisticated and frequently change strategies. They can attack online banking institutions and even steal money from personal or business bank accounts.
Of course, banking malware attacks are nothing new. Most banks have been offering online banking for many years, and criminals have been quick to find ways to exploit this new trend.
Banks quickly realized that they were attractive targets for attackers and responded by strengthening the security of their systems. In turn, criminals soon realized that it was difficult to attack the institutions themselves and so turned to customers.
Stealing customer credentials was an easier method of attack, and that's how the first banking trojans were created. Over the years, criminals have evolved their techniques and created more powerful and insidious malware.
Let's look at some of the most dangerous banking trojan malware that has ever existed:

Emotet
One of the most popular malware. It was first detected by security researchers in 2014 as a simple banking trojan, but soon became one of the most dangerous malware of all time. Later versions were more sophisticated, allowing the installation of other banking trojans on infected machines.
The technique of using one malware to install another is not new. Since September 2018, Emotet has used the Windows EternalBlue vulnerability to spread to a large number of machines.
Also, the main distribution method was malicious attachments within phishing emails, and they were often used as the first stage for a ransomware attack.
In January 2021, Emotet's infrastructure was taken down thanks to a coordinated police operation. However, about two months ago, researchers discovered new attacks from the malware.

Zbot/Zeus
Zeus, also known as Zbot, has been one of the most widespread banking Trojans. It first appeared in 2007 and targeted Windows with the aim of obtaining confidential information from infected computers, mainly through man-in-the-browser attacks and keylogging.
Also, the main distribution method was drive-by downloads and phishing. After installation on the machine, the trojan tried to download configuration files and updates from the Internet.
Zeus files are created and customized using a Trojan-building toolkit, which is available online for cybercriminals.
Zeus was created to steal private data from infected systems, such as system information, passwords, banking credentials, or other financial information.
According to researchers, the trojan's creator has reportedly "retired" and sold the source code to the developer of SpyEye, another banking trojan. However, over the years, several variants have been created.
See also: FinalSite ransomware attack shuts down thousands of school websites
Some are able to evade detection and others were designed to generate revenue through a pay-per-click model. Although the original version of Zeus is largely dealt with by antivirus software, it is still dangerous through its numerous variants.

SpyEye
SpyEye is a data-stealing malware (similar to Zeus) created to steal money from online banking accounts. It was first detected in 2009 and targeted Windows users using popular browsers.
This malware is capable of stealing banking credentials, social security numbers, and financial information that could be used to empty victims' bank accounts.
The SpyEye Trojan contains a keylogger that attempts to steal login credentials for an online banking account. In addition to its activities, SpyEye initially attempted to remove the competing Zeus trojan from target machines.
In 2010, one of the creators of Zeus allegedly shared the source code of the trojan with the developers of SpyEye and they merged the two toolkits. In 2016, a Russian and an Algerian were sentenced to prison for developing and distributing SpyEye.

Shylock
The creators of Shylock clearly had an appreciation for Shakespeare as this trojan was named after the Merchant of Venice. It appeared in July 2011.
Using man-in-the-browser attacks, the trojan stole banking credentials and tricked users into transferring money to accounts controlled by the attackers.
It continued to expand throughout 2012 and maintained its presence until 2014. Unlike other banking trojans, Shylock targeted specific regions, primarily the United Kingdom, although some US banking institutions also appeared on the target list.
In July 2014, an Eastern European gang associated with Shylock was forced to shut down its domains and servers.

TrickBot
TrickBot malware targets user financial information and is usually spread through malicious emails . It was first reported in 2016.
His first targets were banks from Australia, the United Kingdom and Canada, as well as credit card companies from Germany and the United States.
While it was created as a banking Trojan, TrickBot evolved into a modular malware that provides its operators with many tools to conduct a vast number of illegal activities.
It is known to use man-in-the-browser attacks to obtain information such as credentials and can use macros in Excel documents to download and deploy malware on users' devices.
See also: Report: Increase in attacks by ransomware group PYSA, double extortion technique and new tactics
TrickBot is associated with some of the most well-known cyberattacks, as it is often the initial stage for a ransomware attack.

Panda
A variation of Zeus, first discovered in Brazil in 2016.
Panda uses many of Zeus' traditional techniques, including man-in-the-browser (MITB) attacks and keylogging, but it stands out due to its advanced stealth capabilities.
This has made malware analysis more difficult.
A Panda attack can start with spam emails with malicious attachments.
This particular banking malware has targeted financial institutions, cryptocurrency exchange services, as well as social media sites.

DanaBot
It first appeared in mid-2018 targeting Australian users, but then began targeting European banks and email providers, as well as American companies. The DanaBot banking malware has many variants and operates as malware-as-a-service.
The multi-stage infection starts with a dropper that triggers a gradual progression of hacks.
These hacks include stealing network requests, collecting credentials, removing sensitive information, ransomware attacks, screen spying, and installing cryptominers.

Bizarro
Bizarro is one of the latest banking trojans, sweeping mainly Europe and large parts of South America, attempting to steal consumer financial information and mobile crypto wallets.
Many of the victims of this trojan are from Italy, France, Spain, and Portugal, but Bizzaro is believed to originate from Brazil.
The malware spreads either through malicious links contained in spam emails, or through a trojanized application.
After installing malware on the targeted device, the sophisticated backdoor allows criminals to use keyloggers to collect personal login details, as well as command the victim's crypto wallet.
How to protect yourself from banking malware?
What can users do?
- Update all software and systems.
- Download applications and files only from trusted sources.
- Use two-factor authentication, where possible, and implement all the security features offered by the online banking service.
- Use a password manager.
- Training on detecting phishing emails.
What can businesses do?
- Training employees to recognize cyber threats.
- Use a strong and reliable firewall.
- Installation of a privileged access management solution so that no attacker can access the IT infrastructure.
- Use of traffic filtering solution to identify hidden network threats.
